4.3
CVSSv2

CVE-2016-6225

Published: 23/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

xbcrypt in Percona XtraBackup prior to 2.3.6 and 2.4.x prior to 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent malicious users to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

percona xtrabackup

percona xtrabackup 2.4.1

percona xtrabackup 2.4.0

percona xtrabackup 2.4.3

percona xtrabackup 2.4.2

percona xtrabackup 2.4.4

opensuse leap 42.2

opensuse leap 42.1

fedoraproject fedora 25

fedoraproject fedora 24

Vendor Advisories

Debian Bug report logs - #851244 percona-xtrabackup: CVE-2016-6225 Package: src:percona-xtrabackup; Maintainer for src:percona-xtrabackup is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 13 Jan 2017 09:54:02 UTC Severity: grave Tag ...